Fork CMS contains a SQL injection vulnerability in versions prior to version 5.11.1. When deleting submissions which belong to a formular (made with module FormBuilder), the parameter id[] is vulnerable to SQL injection.
{
"nvd_published_at": "2022-03-24T17:15:00Z",
"severity": "HIGH",
"cwe_ids": [
"CWE-89"
],
"github_reviewed": true,
"github_reviewed_at": "2022-03-29T20:36:57Z"
}